Logs for checking please

Discussion in 'Malware Help (A Specialist Will Reply)' started by bowks, Feb 15, 2011.

  1. bowks

    bowks Private First Class

    I cleaned by g'friends computer (had 7 paladin antivirus and other spyware)as per instructions and everything seemed ok, so I went ahead and loaded antivirus and firewalls etc. Except this morning when I tried to open IE I got an error message saying that "Illegal operation attemptd on a registry key that has been marked for deletion". I did a system restore and it seems to be working ok now, so I was wondering if you could check the logs and see if everything really is OK?

    I'm using a Toshiba Satellite laptop with Vista.

    thanks

    Although while I was downloading the logs I notice there is a folder called Paladin Antivirus...so I don't know where I am now...
     

    Attached Files:

  2. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Rebooting the machine will correct that message.

    Have you got the SUPERantispyware log and the logs from running MGTools?
     
  3. bowks

    bowks Private First Class

    Itried to reboot it, I switched it off and on, but maybe it was just sleeping or something and didn't properly reboot. Anyway it seems to be working now.

    Also I couldn't find the MGlogs.zip so I ran the program again and attached that.

    cheers, thanks
     

    Attached Files:

  4. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Logs look good.

    What is inside of this folder?
    c:\windows\system32\Filt

    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.

    REGEDIT4

    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.
     
  5. bowks

    bowks Private First Class

    Thanks for your reply. I had a look but there was no Filt file in c:\windows\system32.

    Also when I tried your instructions I got this error message:
    "X Cannot import C:\Users\cassius\Desktop\fixMe.reg: The specified file is not a registry script. You can only import binary registry files from within the registry editor."

    (I cut and copied it so there shouldn't have been any typo error)

    thanks,

    Gail
     
  6. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    My fault, the registry patch was not correct because I screwed up my formatting. Let's do it again properly.

    Now Copy the bold text below to notepad. Save it as fixME.reg to your desktop. Be sure the "Save as" type is set to "all files" Once you have saved it double click it and allow it to merge with the registry.

    Make sure that you tell me if you receive a success message about adding the above
    to the registry. If you do not get a success message, it definitely did not work.
    It is a folder not a file. Sure no folder of that name exists??
     
  7. bowks

    bowks Private First Class

    It is a folder not a file. Sure no folder of that name exists??[/QUOTE]

    Unless it's hidden? the only files in system32 starting with F were fi-FI and fr-FR.

    Yes! the addition to registry was successful.

    what was that for?

    Gail
     
  8. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    It was to be rid of a remnant from something called ALOT, a toolbar that probably crept in or was installed when installing something else.

    If you are not having any other malware problems, it is time to do our final steps:
    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.
    3. Go back to step 6 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders
      related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.
    10. After doing the above, you should work thru the below link:
     
  9. bowks

    bowks Private First Class

    Thanks very much Kestral.

    I did what you asked, only I couldn't find HijackThis under Programs to delete
    I kept: SuperAntiSpyware, Malwarebytes Antiware and CCleaner
    and installed Outpost Firewall, Spybot and Spyware Blaster.

    I'm not sure what to do with Root Repeal compressed Zip...folder
    and Combofix (notepad file) and Defogger Enable (notepad file) all sitting on the desktop. Should I just delete them?

    cheers

    Gail
     
  10. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Yes you can just delete them :)
     
  11. bowks

    bowks Private First Class

    Thanks. As usual you have been excellent.

    Best wishes.

    Gail
     
  12. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Cheers Gail!

    Safe surfing :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds